Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.453exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.237GitHub PoC 15.653VulnCheck XDB 9134Nuclei 4441Metasploit 3506✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 and PWS - Extended Unicode Directory Traversal (7)
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary comman
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 and PWS - Extended Unicode Directory Traversal (6)
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary comman
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 and PWS - Extended Unicode Directory Traversal (9)
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary comman
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 and PWS - Extended Unicode Directory Traversal (8)
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary comman
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RedHat 6.2 Restore and Dump - Local Privilege Escalation
restore 0.4b15 and earlier in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RealServer 5.0/6.0/7.0 - Memory Contents Disclosure
Real Networks RealServer 7 and earlier allows remote attackers to obtain portions of RealServer's memory contents, possi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RedHat 6.2 - '/sbin/restore' Local Privilege Escalation
restore 0.4b15 and earlier in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle (oidldapd connect) - Local Command Line Overflow
Buffer overflow in oidldapd in Oracle 8.1.6 allow local users to gain privileges via a long "connect" command line param
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
News Update 1.1 - Change Admin Password
CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
LBL Traceroute - Local Privilege Escalation
Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Poll It CGI 2.0 - Multiple Vulnerabilities
pollit.cgi in Poll It 2.01 and earlier allows remote attackers to access administrative functions without knowing the re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joe Kloss RobinHood 1.1 - Remote Buffer Overflow
RHConsole in RobinHood 1.1 web server in BeOS r5 pro and earlier allows remote attackers to cause a denial of service vi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Small HTTP Server 2.0 1 - Non-Existent File Denial of Service
Small HTTP Server 2.03 and earlier allows remote attackers to cause a denial of service by repeatedly requesting a URL t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DCForum 1-6 - Arbitrary File Disclosure
DCForum cgforum.cgi CGI script allows remote attackers to read arbitrary files, and delete the program itself, via a mal
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux modutils 2.3.9 - 'modprobe' Arbitrary Command Execution
modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary commands via shell meta
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Computer Associates InoculateIT 4.53 - Microsoft Exchange Agent
Computer Associates InoculateIT Agent for Exchange Server does not recognize an e-mail virus attachment if the SMTP head
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 2.5/2.5.1/2.6/7.0 - 'sadmind' Remote Buffer Overflow (3)
Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request.
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Indexing Service (Windows 2000) - File Verification
The ixsso.query ActiveX Object is marked as safe for scripting, which allows malicious web site operators to embed a scr
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP-UX 10.20 - registrar Local Arbitrary File Read
registrar in the HP resource monitor service allows local users to read and modify arbitrary files by renaming the origi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
YaBB 9.11.2000 - 'search.pl' Arbitrary Command Execution
Directory traversal vulnerability in YaBB search.pl CGI script allows remote attackers to read arbitrary files via a ..
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 - Executable File Parsing
IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0 - ISAPI Buffer Overflow
Buffer overflow in IIS ISAPI .ASP parsing mechanism allows attackers to execute arbitrary commands via a long string to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RedHat 0.4 b15 restore - Insecure Environment Variables
restore 0.4b15 and earlier in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 2.6/7.0 /locale - Subsystem Format String
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP-UX 9.x/10.x/11.x - cu Buffer Overflow
Buffer overflow in cu program in HP-UX 11.0 may allow local users to gain privileges via a long -l command line argument
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samba 2.0.7 - SWAT Symlink (1)
Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows local users to overwrite arbitrary files via a symlink attack
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ManTrap 1.6.1 - Hidden Process Disclosure
Recourse ManTrap 1.6 does not properly hide processes from attackers, which could allow attackers to determine that they
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samba 2.0.7 - SWAT Logfile Permissions
Samba Web Administration Tool (SWAT) in Samba 2.0.7 installs the cgi.log logging file with world readable permissions, w
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ManTrap 1.6.1 - Root Directory Inode Disclosure
Recourse ManTrap 1.6 sets up a chroot environment to hide the fact that it is running, but the inode number for the resu
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FreeBSD 3.5/4.x - '/usr/bin/top' Format String
Format string vulnerability in top program allows local attackers to gain root privileges via the "kill" or "renice" fun
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.